Beveiligingsadvies

CVE-2016-10044

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-02-07 07:02:00
Laatst bijgewerkt 2024-10-21 13:14:17
Toegewezen door google_android
CVSS-score geen score
Status PUBLISHED

Beschrijving

The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup system call.